Feeds

eBay pulls Vista laptop pwned in hacking contest

Do no harm

The essential guide to IT transformation

An eBay listing for the Windows Vista laptop that was successfully compromised at last week's Pwn2Own hacking contest was removed after the online auctioneer said it violated terms that forbid sales of items that might do harm.

Shane Macaulay, who felled the machine with code that attacked a weakness in Adobe Flash, posted the listing late Monday night, California time. Within two hours, he said in an interview, he received an automated email that said the auction had been suspended.

According to this article by IDG News, the listing read: "This laptop is a good case study for any forensics group/company/individual that wants to prove how cool they are, and a live example, not canned of what a typical incident response sitchiation [sic] would look like."

"At least on the eBay item, I was being a little sensationalistic, but I was just trying to get a sale," he told El Reg. He said he didn't mean to break contest rules that forbid the disclosure of the flaw or exploit code prior to there being a patch.

"By the time they would have gotten it (the laptop), I'm positively sure it would be patched," he said. "The reason i didn't say that outright (was) i wanted to ... see what the market would pay for" the unpatched vulnerability.

Macaulay was one of two attendees to take a prize during last week's contest at the CanSecWest conference in Vancouver. Charlie Miller and two two other researchers from Independent Security Evaluators, won $10,000 for a previously unknown Safari browser exploit that brought down a fully patched MacBook Pro. Macaulay, who was aided by researcher Alex Sotirov, won $5,000 for their exploit. Winners were also permitted to keep the machines. A third laptop running Ubuntu remained standing.

The cash prize is paid by 3Com's Tipping Point division, whose Zero Day Initiative pays bounties to researchers who responsibly disclose vulnerabilities. One condition imposed on sellers is that they provide no details of the vulnerability.

A spokeswoman for eBay told IDG the wording of Macaulay's listing led them to think the laptop could do someone harm. ®

Next gen security for virtualised datacentres

More from The Register

next story
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Germany 'accidentally' snooped on John Kerry and Hillary Clinton
Dragnet surveillance picks up EVERYTHING, USA, m'kay?
Snowden on NSA's MonsterMind TERROR: It may trigger cyberwar
Plus: Syria's internet going down? That was a US cock-up
Who needs hackers? 'Password1' opens a third of all biz doors
GPU-powered pen test yields more bad news about defences and passwords
Think crypto hides you from spooks on Facebook? THINK AGAIN
Traffic fingerprints reveal all, say boffins
Rupert Murdoch says Google is worse than the NSA
Mr Burns vs. The Chocolate Factory, round three!
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
prev story

Whitepapers

5 things you didn’t know about cloud backup
IT departments are embracing cloud backup, but there’s a lot you need to know before choosing a service provider. Learn all the critical things you need to know.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.